67%
Total Score
caution
Usable with caveats: recent releases exist, but commit activity has stopped and workflow dependencies are unpinned.
There were no commits and no active maintainers in the last 3 months. Although the recent release provides some compensating evidence, the short-term absence of development activity lowers confidence in ongoing maintenance.
The repository uses Make and Composer, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is not severe enough to make the release unfit on its own.
Version 0.5.3 is not a prerelease, and no recent releases are prereleases, which supports adoption. It remains below a stable major version, so some API evolution risk remains.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or write-wide permissions, but all 6 action references are unpinned. That leaves avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.7|^3.0 | — | — |
symfony/http-foundation Version ^5.4|^6.4|^7.0|^8.0 | — | — |
symfony/framework-bundle Version ^5.4|^6.4|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.